UbuntuUpdates.org

Package "golang-1.21-go"

Name: golang-1.21-go

Description:

Go programming language compiler, linker, compiled stdlib

Latest version: 1.21.9-1ubuntu0.1
Release: noble (24.04)
Level: updates
Repository: universe
Head package: golang-1.21
Homepage: https://go.dev/

Links


Download "golang-1.21-go"


Other versions of "golang-1.21-go" in Noble

Repository Area Version
base universe 1.21.9-1
security universe 1.21.9-1ubuntu0.1

Changelog

Version: 1.21.9-1ubuntu0.1 2024-07-09 16:07:12 UTC

  golang-1.21 (1.21.9-1ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: denial of service issue
    - debian/patches/CVE-2024-24789.patch: archive/zip: treat truncated
      EOCDR comment as an error
    - debian/source/include-binaries: Add zip testdata file
    - CVE-2024-24789
  * SECURITY UPDATE: incorrect IPv4-mapped IPv6 addresses issue
    - debian/patches/CVE-2024-24790.patch: net/netip: check if address is
      v6 mapped in Is methods
    - CVE-2024-24790

 -- Nishit Majithia <email address hidden> Mon, 08 Jul 2024 17:17:17 +0530

CVE-2024-24789 The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment cou
CVE-2024-24790 The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which woul



About   -   Send Feedback to @ubuntu_updates